icono de lupa

ENS high category, ISO 27001, GDPR and NIS2

Regulatory mapping and compliance

Transparent Edge is certified under the ENS high category and ISO/IEC 27001:2022 standards, and acts as a data processor under the GDPR. To demonstrate compliance with your web perimeter and API, here are the details of the measures the platform covers, the level of coverage, and the evidence you can provide for an audit or other requirements. The full document for each standard is available for download.

What do we resolve?

Transparent Edge covers the technical measures of the ENS high category and the controls of Annex A of ISO 27001 that affect your web perimeter and API: WAF, anti-DDoS, Bot Management, managed encryption with TLS and post-quantum cryptography, logs with two-year retention, and automatic detection of traffic anomalies. In the event of an audit, the Transparent Edge link in your supply chain is fully implemented, with current certification, a defined scope, and downloadable evidence.

European jurisdiction

Own infrastructure, company and data within the European Union. No international transfers to document in your record of processing activities, and without the concentration risk that Article 21.2 d) of NIS2 requires you to assess in the supply chain.

ENS high category

Certification in the most demanding category of Royal Decree 311/2022. The National Security Framework (ENS) is mandatory for the Spanish public sector and its ICT providers. The high category covers systems where an incident would cause very serious harm, and its Annex II contains 73 measures. It is audited every two years by an accredited entity.

For a government body, this fulfills point op.ext.3 regarding supply chain protection.

ISO/IEC 27001:2022

An accredited external auditor verifies annually that Transparent Edge’s processes function as documented: threat intelligence, configuration management, change control, monitoring, and incident response. The certification is issued against the 2022 version of the standard, which added cloud service controls and web filtering. The scope covers the platform and its operation.

GDPR

Data processing agreement included in the service contract. The platform does not track end users. Encrypted logs in transit and at rest, with a two-year retention period by default and a formal deletion policy. Infrastructure and jurisdiction in the European Union.

NIS2

The platform covers the technical measures that NIS2 requires for the web and API perimeter: detection, automated mitigation, continuity, encryption, and access control. The Transparent Edge platform monitors 24/7 and takes action without you having to look at the dashboard. If an incident reaches the thresholds of Regulation (EU) 2024/2690, you receive the timeline, IPs, and attack patterns that your CSIRT notification requires.

Auditable evidence

Everything that passes through the edge is logged and delivered to you: HTTP and HTTPS requests, WAF events, Bot Management and anti-DDoS decisions, panel accesses, and configuration changes with author and timestamp. Raw data is delivered via Kafka queue or in batches via SFTP.
Integrable with Splunk, Elastic, or Sentinel.

Post-quantum cryptography

The TLS 1.3 handshake is negotiated using ML-KEM and is enabled by default for all compatible traffic without any configuration required. If the browser does not support it, classic ECDHE is used. The session key is derived from the most secure algorithm supported by the client, so traffic captured today remains protected against “harvest now, decrypt later” attacks, even before the availability of quantum computers.

ENS high category
(RD 311/2022, Annex II)

PLATFORM COVERAGE

  • Access control (op.acc.1, 2, 5 and 6): unique user identification with available SSO and SAML, granular roles on the panel, MFA and authentication with WebAuthn/FIDO2 passkey.
  • Exploitation (op.exp.1 to op.exp.10): automatic inventory of domains, certificates and rules. Versioning of VCL configurations and WAF rules with author and timestamp, accessible via API. Patched and updates under SLA. Encrypted logs with two years of retention, expandable by contract.
  • Monitoring (op.mon.1 to op.mon.3): anomaly detection, WAF and Bot Management functioning as an application-wide IDS and IPS. 24/7 monitoring by a dedicated SOC team, configurable alerts, and automated responses.
  • Continuity (op.cont.2, 3 and 4): Over 70 PoPs in more than 40 countries. Failover between PoPs is continuously tested in production. Dedicated or licensed CDN as an alternative, as required by op.cont.4 in the high category.
  • Communications protection (mp.com.1 to mp.com.4): Application perimeter with Layer 3 to Layer 7 filtering. Managed TLS with post-quantum cryptography. Optional mTLS to the origin. Multi-tenant logical isolation and physical separation with dedicated CDN.
  • Web services (mp.s.2 and mp.s.3): WAF, anti-DDoS, Bot Management, IP Analysis and Anomaly Detection, with 950 Gbps of aggregate capacity (May 2026).

PENDING ON YOUR PART

  • Complete organizational framework (org.*): security policy, regulations, procedures, and authorization process.
  • Personnel (mp.per.*): job descriptions, duties and responsibilities, awareness, and training.
  • Facilities (mp.if.*): separate areas, physical access control, electrical power, and climate control.
  • Developing your applications (mp.sw.1): in the high category, this measure is your responsibility. Transparent Edge follows its own SDLC, audited within its ISMS.
  • Email (mp.s.1) and information qualification (mp.info.2): outside the functional scope of an edge web and API provider.
PLATFORM COVERAGE
  • Access control (op.acc.1, 2, 5 and 6): unique user identification with available SSO and SAML, granular roles on the panel, MFA and authentication with WebAuthn/FIDO2 passkey.
  • Exploitation (op.exp.1 to op.exp.10): automatic inventory of domains, certificates and rules. Versioning of VCL configurations and WAF rules with author and timestamp, accessible via API. Patched and updates under SLA. Encrypted logs with two years of retention, expandable by contract.
  • Monitoring (op.mon.1 to op.mon.3): anomaly detection, WAF and Bot Management functioning as an application-wide IDS and IPS. 24/7 monitoring by a dedicated SOC team, configurable alerts, and automated responses.
  • Continuity (op.cont.2, 3 and 4): Over 70 PoPs in more than 40 countries. Failover between PoPs is continuously tested in production. Dedicated or licensed CDN as an alternative, as required by op.cont.4 in the high category.
  • Communications protection (mp.com.1 to mp.com.4): Application perimeter with Layer 3 to Layer 7 filtering. Managed TLS with post-quantum cryptography. Optional mTLS to the origin. Multi-tenant logical isolation and physical separation with dedicated CDN.
  • Web services (mp.s.2 and mp.s.3): WAF, anti-DDoS, Bot Management, IP Analysis and Anomaly Detection, with 950 Gbps of aggregate capacity (May 2026).
PENDING ON YOUR PART
  • Complete organizational framework (org.*): security policy, regulations, procedures, and authorization process.
  • Personnel (mp.per.*): job descriptions, duties and responsibilities, awareness, and training.
  • Facilities (mp.if.*): separate areas, physical access control, electrical power, and climate control.
  • Developing your applications (mp.sw.1): in the high category, this measure is your responsibility. Transparent Edge follows its own SDLC, audited within its ISMS.
  • Email (mp.s.1) and information qualification (mp.info.2): outside the functional scope of an edge web and API provider.
download

National Security Scheme (ENS)

Discover the points you have covered with this detailed regulatory mapping sheet

ISO/IEC 27001:2022
(Annex A)

DIRECT COVERAGE

  • A.5.7 Threat intelligence. IP Analysis, reputation lists, malicious datacenter ASNs, and proprietary feeds feeding rules in real time.
  • A.5.23, A.5.29 and A.5.30. European cloud platform with documented segregation and shared responsibility model. The cache continues to deliver even with the origin down. Continuously tested multi-PoP failover.
  • A.8.7, A.8.8, and A.8.23. The WAF stops RCE, web shell installation, and malicious code deployment vectors, and performs virtual patching while you fix the vulnerability. Reverse web filtering. Bot management against scrapers and automated exploitation tools.
  • A.8.15, A.8.16, and A.8.17. Traffic logs, security decisions, panel access, and configuration changes. Raw delivery via Kafka queue or batch delivery via FTP and SFTP. NTP synchronization with UTC timestamp.
  • A.8.9 and A.8.32. Versioning and traceability of rules and policies, formal workflow of changes audited in ENS and ISO 27001, with rollback capability.
  • A.8.6 and A.8.14. Horizontal scaling across more than 70 PoPs, 950 Gbp aggregate against DDoS (May 2026), multi-region and instant failover.
  • A.8.5 Secure authentication. MFA and WebAuthn/FIDO2 passkey in the panel. Bot Management as an additional layer against credential stuffing in your applications.

PENDING ON YOUR PART

  • A.6 on people controls. Selection, contractual terms, awareness, disciplinary process, asset return, and confidentiality agreements. The platform reduces the exposed surface in A.6.7 teleworking when you publish internal applications behind the edge.
  • A.5.1, and A.5.19 to A.5.22. Your security policy and supplier management.
    Transparent Edge is an evaluable supplier: ENS high, ISO 27001 and GDPR compliance facilitate your due diligence.
  • A.8.1 end user devices.
  • A.8.12 Information leakage prevention. Transparent Edge does not inspect outbound response traffic and does not implement DLP. It blocks vectors that would enable exfiltration (injection, RCE, web shells, malicious scraping). DLP control itself requires a specialized product.
  • A.8.11 Data masking. With VCL programmability, you can manipulate response headers and metadata to remove sensitive fields. Masking PII within the response body requires custom development.
  • A.8.25 to A.8.30. Secure development and secure coding of your applications.
DIRECT COVERAGE
  • A.5.7 Threat intelligence. IP Analysis, reputation lists, malicious datacenter ASNs, and proprietary feeds feeding rules in real time.
  • A.5.23, A.5.29 and A.5.30. European cloud platform with documented segregation and shared responsibility model. The cache continues to deliver even with the origin down. Continuously tested multi-PoP failover.
  • A.8.7, A.8.8, and A.8.23. The WAF stops RCE, web shell installation, and malicious code deployment vectors, and performs virtual patching while you fix the vulnerability. Reverse web filtering. Bot management against scrapers and automated exploitation tools.
  • A.8.15, A.8.16, and A.8.17. Traffic logs, security decisions, panel access, and configuration changes. Raw delivery via Kafka queue or batch delivery via FTP and SFTP. NTP synchronization with UTC timestamp.
  • A.8.9 and A.8.32. Versioning and traceability of rules and policies, formal workflow of changes audited in ENS and ISO 27001, with rollback capability.
  • A.8.6 and A.8.14. Horizontal scaling across more than 70 PoPs, 950 Gbp aggregate against DDoS (May 2026), multi-region and instant failover.
  • A.8.5 Secure authentication. MFA and WebAuthn/FIDO2 passkey in the panel. Bot Management as an additional layer against credential stuffing in your applications.
PENDING ON YOUR PART
  • A.6 on people controls. Selection, contractual terms, awareness, disciplinary process, asset return, and confidentiality agreements. The platform reduces the exposed surface in A.6.7 teleworking when you publish internal applications behind the edge.
  • A.5.1, and A.5.19 to A.5.22. Your security policy and supplier management.
    Transparent Edge is an evaluable supplier: ENS high, ISO 27001 and GDPR compliance facilitate your due diligence.
  • A.8.1 end user devices.
  • A.8.12 Information leakage prevention. Transparent Edge does not inspect outbound response traffic and does not implement DLP. It blocks vectors that would enable exfiltration (injection, RCE, web shells, malicious scraping). DLP control itself requires a specialized product.
  • A.8.11 Data masking. With VCL programmability, you can manipulate response headers and metadata to remove sensitive fields. Masking PII within the response body requires custom development.
  • A.8.25 to A.8.30. Secure development and secure coding of your applications.
download

Regulatory mapping for ISO 27001

Discover the areas you’ve got covered with Transparent Edge

NIS2
(EU Directive 2022/2555)

AREAS OF ART. 21.2 WITH COVERAGE

  • b) Incident management. Anomaly detection and Perimetrical as an automatic detection and mitigation layer, with its own 24/7 SOC. Forensic data for notification. Regulation (EU) 2024/2690 sets the criteria for a significant incident for CDNs: interruption of more than 25% of users or of more than five minutes, among others.
  • c) Business continuity and crisis management. Multi-PoP network with automatic failover. The cache supports delivery when the origin is down. Dedicated or licensed CDN as an alternative.
  • d) Supply chain security. ICT provider certified in ENS high and ISO 27001, with European jurisdiction, which lowers your concentration risk.
  • e) Vulnerability Management. Virtual mitigation with WAF while patching. Anomaly detection identifies vulnerabilities through passive analysis of traffic patterns, without active scanning. Responsible disclosure policy.
  • f) Effectiveness of the measures. Dashboard with blocked requests, mitigated attacks, latency, and real-time errors. Periodic reports. Logs available for external auditing.
  • h) Cryptography and encryption. Managed TLS 1.2 and 1.3, automatic certificate rotation, post-quantum suite available, optional mTLS to the origin.
  • j) MFA and authenticated communications. MFA is available and recommended for all panel users. Administrative communications are supported via HTTPS, SSH, and mTLS.

AREAS THAT DEPEND ON YOUR ORGANIZATION

  • a) Information systems risk and security analysis policies. The platform gives you visibility into risks across the web and API perimeter and supports the analysis of internet-exposed assets. The methodology and policy are yours.
  • g) Cyber ​​hygiene and training. Transparent Edge provides technical training to your team on the secure use of the platform. General staff and management training is your responsibility.
  • i) Human resources, access control, and asset management. The platform covers logical access control to the dashboard and the service’s asset inventory. Onboarding, offboarding, and physical access are all under your control.
  • Registration as an essential or important entity, notification to the relevant CSIRT and the responsibility of the governing bodies.
AREAS OF ART. 21.2 WITH COVERAGE
  • b) Incident management. Anomaly detection and Perimetrical as an automatic detection and mitigation layer, with its own 24/7 SOC. Forensic data for notification. Regulation (EU) 2024/2690 sets the criteria for a significant incident for CDNs: interruption of more than 25% of users or of more than five minutes, among others.
  • c) Business continuity and crisis management. Multi-PoP network with automatic failover. The cache supports delivery when the origin is down. Dedicated or licensed CDN as an alternative.
  • d) Supply chain security. ICT provider certified in ENS high and ISO 27001, with European jurisdiction, which lowers your concentration risk.
  • e) Vulnerability Management. Virtual mitigation with WAF while patching. Anomaly detection identifies vulnerabilities through passive analysis of traffic patterns, without active scanning. Responsible disclosure policy.
  • f) Effectiveness of the measures. Dashboard with blocked requests, mitigated attacks, latency, and real-time errors. Periodic reports. Logs available for external auditing.
  • h) Cryptography and encryption. Managed TLS 1.2 and 1.3, automatic certificate rotation, post-quantum suite available, optional mTLS to the origin.
  • j) MFA and authenticated communications. MFA is available and recommended for all panel users. Administrative communications are supported via HTTPS, SSH, and mTLS.
AREAS THAT DEPEND ON YOUR ORGANIZATION
  • a) Information systems risk and security analysis policies. The platform gives you visibility into risks across the web and API perimeter and supports the analysis of internet-exposed assets. The methodology and policy are yours.
  • g) Cyber ​​hygiene and training. Transparent Edge provides technical training to your team on the secure use of the platform. General staff and management training is your responsibility.
  • i) Human resources, access control, and asset management. The platform covers logical access control to the dashboard and the service’s asset inventory. Onboarding, offboarding, and physical access are all under your control.
  • Registration as an essential or important entity, notification to the relevant CSIRT and the responsibility of the governing bodies.
download

Regulatory mapping to complete NIS2

Discover the areas you’ve got covered with Transparent Edge

GDPR and data protection

WHAT TRANSPARENT EDGE PROVIDES

  • Data processor agreement included in the service contract, with the obligations of Art. 28.
  • No end-user tracking. The platform does not create profiles or its own tracking cookies.
  • Infrastructure, society and jurisdiction in the European Union. No international transfers to justify.
  • Art. 32 encryption. End-to-end managed TLS with post-quantum support, encrypted logs in transit and at rest, mTLS to the origin optional.
  • Log retention is two years by default, extendable or reduced by contract. A formal policy is in place for deleting logs from the file system once the retention period has expired.
  • Support for Art. 33 breach notification. Automatic detection and forensic evidence (logs, IP, attack patterns) to ensure you have data within your 72-hour deadline.
  • Backups of configurations and traffic data processed by the platform. You can download and store your own copy via API.

WHAT REMAINS ON YOUR SIDE

  • Legal basis for processing, information for data subjects, and consent management.
  • Record of processing activities under Article 30, and impact assessment where applicable.
  • Addressing the rights of data subjects regarding data held by you.
  • Minimization and masking of personal data in the content you serve.
  • Your own sub-processors and the rest of your processing chain.
WHAT TRANSPARENT EDGE PROVIDES
  • Data processor agreement included in the service contract, with the obligations of Art. 28.
  • No end-user tracking. The platform does not create profiles or its own tracking cookies.
  • Infrastructure, society and jurisdiction in the European Union. No international transfers to justify.
  • Art. 32 encryption. End-to-end managed TLS with post-quantum support, encrypted logs in transit and at rest, mTLS to the origin optional.
  • Log retention is two years by default, extendable or reduced by contract. A formal policy is in place for deleting logs from the file system once the retention period has expired.
  • Support for Art. 33 breach notification. Automatic detection and forensic evidence (logs, IP, attack patterns) to ensure you have data within your 72-hour deadline.
  • Backups of configurations and traffic data processed by the platform. You can download and store your own copy via API.
WHAT REMAINS ON YOUR SIDE
  • Legal basis for processing, information for data subjects, and consent management.
  • Record of processing activities under Article 30, and impact assessment where applicable.
  • Addressing the rights of data subjects regarding data held by you.
  • Minimization and masking of personal data in the content you serve.
  • Your own sub-processors and the rest of your processing chain.